A vulnerability marked as very critical has been reported in Foreman. The impacted element is an unknown function of the component foreman-tail. The manipulation leads to command injection. This vulnerability is documented as CVE-2026-12542. The attack can be initiated remotely. There is not any exploit available. Weiterlesen: CVE-2026-12542 | Foreman foreman-tail command injection (WID-SEC-2026…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-12542 | Foreman foreman-tail command injection (WID-SEC-2026-3712)
A vulnerability marked as very critical has been reported in Foreman. The impacted element is an unknown function of the component foreman-tail. The…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CVSS 5.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Impact: 3.37 | Exploitability: 1.83
AVL
Lokal (Dateisystem / SSH)
Erfordert bereits ein lokales Benutzerkonto oder Ausführung vor Ort.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CL
Gering (Teilabfluss)
Teilweiser oder kein Datenabfluss.
IL
Gering (Teilweise)
Teilweise oder keine Manipulation.
AL
Gering (Drosselung)
Teilweise oder keine Beeinträchtigung.
NVD Primärbewertung & CISA SSVCCVE-2026-12542
NVD: Awaiting AnalysisNVD 5.3 · MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
NVD-Datenstand: 02.10.2026, 18:17 UTC
BSI-Warnung (Deutschland)CVE-2026-12542
Foreman: Mehrere Schwachstellen kritisch01.10.2026
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Red Hat Security Bulletin Verifiziertredhat.com